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TOP SECRET//COMINT//20291123 


(U//FOUO) CLASSIFICATION GUIDE TITLE/NUMBER: 
(U) PUBLICATION DATE: 13 September 2005 
(U) OFFICE OF ORIGIN: 


(U/FOUO) POC: 


(U//FOUO) PHONE: 


(U/FOUO) ORIGINAL CLASSIFICATION AUTHORITY: 


Classification/ 
Markings 


Description of Information 


(U) The fact that NSA/CSS exploits 


i UNCLASSIFIED N/A 
cryptographic information security devices 
and systems. 


2. (C) The fact that NSA/CSS works with 
Second Party partners on exploiting 


CONFIDENTIAL | 1.4(c) | 20291123 
cryptographic information security devices 
and systems. 
SECRET 1.4 (c) | 20291123 


(S) The fact that NSA/CSS works with 
unspecified Third Party partners on 
exploiting cryptographic information 
security devices and systems. 

(U) The fact that NSA/CSS exploits 


(TS//S]) The fact that NSA/CSS makes 
cryptographic modifications to commercial 
or indigenous cryptographic information 
security devices or systems in order to 
make them exploitable. 

(U) The fact that NSA/CSS has 
cryptanalytic techniques to exploit 
cryptographic components of commercial 
or indigenous information security devices 
or systems. 

(C) The fact that NSA/CSS has the ability 
to recover cryptovariables used to exploit 
commercial or indigenous cryptographic 
information security devices or systems. 


TOP SECRET// 
COMINT 


ata minimum 


CONFIDENTIAL 


2 


Reason 


N/A 
UNCLASSIFIED N/A N/A 
unintended cryptographic vulnerabilities in 
commercial or indigenous information 
security devices and systems, as long as 
neither the vulnerability nor the targeted 
device/ system is identified. 
N/A 


CRYPTANALYSIS Guide 02-12 


Cryptanalysis & Exploitation Services (S31) 


Declass Remarks 


1.4(c) | 20291123 | (U) Specifying the specific system 
is protected by an ECI.. 
UNCLASSIFIED N/A (U) Additional details will raise 
the classification and may be 
protected by an ECI. 
1.4 (c) | 20291123 | (C) Details of CV recovery are 
protected by an ECI. 
(C) Specifying a specific system 
for which we can recovery CVs is 
protected by an ECI. 
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TOP SECRET//COMINT//20291123 


Remarks 


Declass 


Reason 


Classification/ 
Markings 
UNCLASSIFIED N/A N/A 


Description of Information 


(U) The fact that NSA/CSS successfully 

exploits cryptographic components of 

commercial or indigenous cryptographic 

information security devices or systems 

without specifying the device or system. 

9. (U//FOUO) The fact that NSA/CSS 
successfully exploits cryptographic 
components of commercial or indigenous 
cryptographic information security devices 
or systems when the device or system is 
specified. 

10. (TS) The fact that NSA/CSS obtains 
cryptographic details of commercial 
cryptographic information security systems 
through industry relationships. 


(U) Additional details will require 
the classification and may be 
protected by an ECI. 


TOP SECRET// 
COMINT 
at a minimum 


20291123 | (U) Additional details may be 


protected by an ECI. 


TOP SECRET 
at a minimum 


20291123 | (C) Identification of the system or 
company is protected as COMINT 


and ECI. 


(U) DEFINITIONS: 


(U//FOUO) Information security device or system: A device or system that provides any of the following services for 
communications or information systems: confidentiality, data integrity, authentication and authorization. 


(U/(FOUO) Cryptanalytic vulnerability: A flaw in the design, implementation or system integration of cryptography used in an 
information security device, or a flaw in the way that a cryptographic information security device is used. 


(U//FOUO) Unintended cryptographic vulnerability: Security is less than advertised by the manufacturer. 


(U//FOUO) Indigenous: Non-commercial cryptographic information security system or device developed by a SIGINT target. 
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